Threat Intelligence Engineer
Core
Research, collect, and analyze threat data to detect and respond to threats targeting the enterprise and its software supply chain.
Role type
Threat Intelligence Engineer
Builds
Intelligence products, indicator pipelines, and threat context for security workflows
Domain
Cybersecurity / Software Supply Chain Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Threat intelligence lifecycle, threat actor profiling, MITRE ATT&CK mapping, SIEM/EDR operations, open-source ecosystem adversarial techniques, structured intelligence formats (STIX 2.1), alert triage, detection logic testing
Preferred skills
Bachelor's degree in CS/InfoSec, entry-level security certification
Technologies
Sumo Logic, CrowdStrike Falcon/NG SIEM, npm, PyPI, Go, Maven, Recorded Future
Responsibilities
Ingest and score IOCs from commercial and open-source feeds; monitor package registries and CI/CD pipelines for adversarial activity; draft threat actor profiles and campaign summaries; support integration of IOC pipelines with SIEM/EDR platforms; assist CSIRT and Vulnerability Management with alert triage and investigation enrichment; prepare threat intelligence summaries for internal consumers
Seniority
Mid-level, hands-on IC